Methodology

How a review runs

A repeatable path for application security event and anomaly analytics engagements, designed so owners always know what happens next.

Our flagship Security Event Analytics Review follows five stages. Investigations and workshops borrow the same discipline at a shorter length.

  1. Scope and constraints

    We confirm applications in scope, event stores, privacy limits, and the decisions you need the review to support. You receive a written fee basis before samples move.

  2. Sample window

    Together we choose a contiguous window — often seven to fourteen days — plus any known anomaly periods. Exports or limited read access are arranged so production change freezes are respected.

  3. Event inventory

    We catalogue security-relevant events: authentication outcomes, authorization denials, privilege changes, and other application decisions that should leave a trail.

  4. Anomaly and coverage analysis

    Using the inventory, we test whether abuse scenarios and silence conditions can be answered. Findings are ranked by decision value, not chart density.

  5. Delivery and clarification

    You receive a written report, a walkthrough meeting, and two clarification calls within thirty days. Remediation owners are named where your org chart allows.

What you prepare

  • A technical contact per application
  • Architecture sketch of event producers and stores
  • Notes on known quirks: duplicates, clock skew, dual logging
  • Any PIPA or contractual limits on field sharing

Ready to put a review on the calendar?

Browse engagements or send a short brief describing the applications you want examined.